Vulnerabilities (CVE)

Filtered by CWE-522
Total 1485 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2010-4178 2 Fedoraproject, Oracle 2 Fedora, Mysql-gui-tools 2026-06-16 2.1 LOW 5.5 MEDIUM
MySQL-GUI-tools (mysql-administrator) leaks passwords into process list after with launch of mysql text console
CVE-2007-0681 1 Extcalendar Project 1 Extcalendar 2026-06-16 7.5 HIGH 9.8 CRITICAL
profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, and possibly perform other unauthorized actions, via modified values to register.php.
CVE-2005-3435 1 Archilles 1 Newsworld 2026-06-16 7.5 HIGH 9.8 CRITICAL
admin_news.php in Archilles Newsworld up to 1.3.0 allows attackers to bypass authentication by obtaining the password hash for another user, for example through another Newsworld vulnerability, and specifying the hash in the pwd argument.
CVE-2000-0944 1 Cgi 1 Script Center News Update 2026-06-16 7.5 HIGH 9.8 CRITICAL
CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, which allows remote attackers to modify the password without knowing the original password.
CVE-1999-0013 1 Ssh 1 Ssh 2026-06-16 7.5 HIGH 8.4 HIGH
Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent user.